CISM Audible Exam Quiz Phil Martin Flashcards
standard
tells how to carry out a policy
procedure
clear list of steps required to accomplish a task
procedure defines 4 things
required conditions
information displayed
expected outcome
what to do when unexpected happens
biased assimilation
when we accept only facts that support our perspective
risk appetite
amount of risk a business is willing to incur
risk tolerance
amount of deviation from the risk appetite that a business considers acceptable
risk capacity
amount of risk a business can absorb without dying
3 phases of octave
locate all assets, build threat profile
locate all network paths and it components
assign risk to each asset and decide what to do with it
operationally critical threat asset and vulnerability evaluation (OCTAVE)
risk approach for when you need well established process to id, prioritize and manage risk
Bowtie analysis
risk approach that creates a visual diagram with the event in the middle (knot)